<<

DATASHEET

FortiGate®-3040B/3140B 10-GbE Consolidated Security Appliances

FortiGate-3040B and FortiGate-3140B consolidated security appliances offer exceptional levels of performance, deployment flexibility, and security for large enterprise networks. Built from the ground up by Fortinet, these appliances deliver superior performance through a combination of custom hardware, including FortiGate-3040B/3140B Benefits FortiASIC™ processors, high port density, and consolidated security features from • Outstanding value as 10-GbE the FortiOS™ operating system. Whether protecting virtualized infrastructure, network security appliances cloud-providing infrastructure, or traditional IT infrastructure, 10-Gigabit Ethernet with best-in-class firewall (10-GbE) ports and up to 58 Gbps of firewall throughput make these appliances price-performance ideal for securing high-bandwidth networks. • Highest 10-GbE port density in their class High-Performance Hardware The FortiGate-3140B appliance provides up to 58 Gbps of firewall throughput • Active Profiling provides behavioral analysis and active and the FortiGate-3040B delivers up to 40 Gbps of firewall performance through response to abnormal behavior the use of innovative FortiASIC processors and the latest generation of general purpose CPUs. Impressive consolidated security performance and support for a • Complete Content Protection provides application control variety of configurations ensure that essential security functions keep up with the coupled with identity-based rest of your network. policy enforcement High 10-GbE Port Density • IPv6 certified platform You can protect your data center and other high-bandwidth applications with • Strong authentication options the 10-GbE interfaces that ship standard on the FortiGate-3040B/3140B for policy compliance appliances. Each platform includes system ports supporting SFP+, SFP, and RJ-45 connections, providing maximum flexibility. Consolidated Security Using the advanced FortiOS operating system, FortiGate-3040B/3140B appliances effectively neutralize a wide range of network security threats. Whether deployed as high-performance firewalls or as comprehensive multi-threat security solutions, these dedicated appliances protect assets with some of the most effective security available today.

FortiGate Certifications

Data Center

10-GbE

1-GbE LAN FortiGate-3040B / 3140B

Ideal for protecting datacenters and enabling cloud services (IaaS and SaaS) The FortiASIC Advantage FortiGate-3040B/3140B appliances include our latest FortiASIC Network Processors (NP) and Content Processors (CP). These purpose-built, high- performance processors use proprietary digital engines to accelerate resource- FortiASIC™- NP4 intensive security services. 0849 A905ES The FortiASIC NP4 works inline with firewall and VPN functions delivering: • Wire-speed firewall performance for any size packets • VPN acceleration • Anomaly-based intrusion prevention, checksum offload and packet defragmentation • Traffic shaping and priority queuing

The FortiASIC CP7 works outside of the direct flow of traffic, providing high- speed cryptography and content inspection services including: • Encryption and decryption offloading FortiASIC-CP7 TS4KJ-000 • Signature-based content inspection acceleration 0846 CO FortiGate-3140B appliance includes the custom FortiASIC Security Processor (SP) chip. The FortiASIC SP2 provides additional intrusion prevention system (IPS) and firewall acceleration for the most demanding environments.

FortiGate-3040B Appliance (Front) FortiGate-3040B Appliance (Back)

FortiGate-3140B Appliance (Front) FortiGate-3140B Appliance (Back)

FortiGuard® Security Subscription Services deliver dynamic, automated updates for Fortinet products. The Fortinet Global Security Research Team creates these updates to ensure up-to-date protection against sophisticated threats. Subscriptions include antivirus, intrusion prevention, web filtering, antispam, vulnerability management, application control, and database security services. For more information about FortiGuard Services, please visit www.fortiguard.com.

FortiCare™ Support Services provide global support for all Fortinet products and services. FortiCare support enables your Fortinet products to perform optimally. Support plans start with 8x5 Enhanced Support with return and replace hardware support or 24x7 Comprehensive Support with advanced hardware replacement. Options include Premium Support, Premium RMA, and Professional Services. All hardware products include a 1-year limited hardware warranty and a 90-day limited software warranty. Additionally, Fortinet Professional Services can be engaged to expedite critical projects and initial deployments.

FortiGuard Subscription Services Intrusion Application Vulnerability Products Antivirus Web Filtering Antispam Prevention Control Management FortiGate-3040B Supported Supported Supported Supported Supported Supported FortiGate-3140B Supported Supported Supported Supported Supported Supported FortiOS 4.0 Software—Raising The Bar

FortiOS 4.0: Redefining Network Security Fortinet’s ASIC-Based Advantage FortiOS 4.0 is the software foundation of FortiGate multi- FortiASICs are a family of purpose-built, high performance threat security platforms. Developed solely for security, processors that use an intelligent proprietary content performance, and reliability, it is a purpose-built operating scanning engine and multiple algorithms to accelerate system that leverages the power of FortiASIC processors. security and network services.

FortiOS Security Services

FIREWALL ANTIVIRUS / ANTISPYWARE INTRUSION PREVENTION SYSTEM (IPS) ICSA Labs Certified (Enterprise Firewall) ICSA Labs Certified (Gateway Antivirus) ICSA Labs Certified (NIPS) NAT, PAT, Transparent (Bridge) Includes Antispyware and Worm Prevention: Protection From Over 3000 Threats Routing Mode (RIP, OSPF, BGP, Multicast) HTTP/HTTPS SMTP/SMTPS Protocol Anomaly Support Policy-Based NAT POP3/POP3S IMAP/IMAPS Custom Signature Support Virtual Domains (NAT/Transparent mode) FTP IM Protocols Automatic Attack Database Update VLAN Tagging (802.1Q) Flow-Based Antivirus Scanning Mode IPv6 Support Group-Based Authentication & Scheduling Automatic “Push” Content Updates SIP/H.323 /SCCP NAT Traversal File Quarantine Support DATA LOSS PREVENTION (DLP) WINS Support Databases: Standard, Extended, Extreme, Flow Identification and Control Over Sensitive Data in Explicit Proxy Support (Citrix/TS etc.) IPv6 Support Motion VoIP Security (SIP Firewall/RTP Pinholing) Built-in Pattern Database Granular Per-Policy Protection Profiles WEB FILTERING RegEx-based Matching Engine for Customized Identity/Application-Based Policy 76 Unique Categories Patterns Vulnerability Management FortiGuard Web Filtering Service Categorizes over 2 Configurable Actions (block/log) IPv6 Support (NAT/Transparent mode) Billion Web pages Supports IM, HTTP/HTTPS, and More HTTP/HTTPS Filtering Many Popular File Types Supported VIRTUAL PRIVATE NETWORK (VPN) Web Filtering Time-Based Quota International Character Sets Supported ICSA Labs Certified (IPSec) URL/Keyword/Phrase Block PPTP, IPSec, and SSL Dedicated Tunnels URL Exempt List ANTISPAM SSL-VPN Concentrator (incl. iPhone support) Content Profiles Support for SMTP/SMTPS, POP3/POP3S, IMAP/ DES, 3DES, and AES Encryption Support Blocks Java Applet, Cookies, Active X IMAPS SHA-1/MD5 Authentication MIME Content Header Filtering Real-Time Blacklist/Open Relay Database Server PPTP, L2TP, VPN Client Pass Through IPv6 Support MIME Header Check Hub and Spoke VPN Support Keyword/Phrase Filtering IKE Certificate Authentication (v1 & v2) APPLICATION CONTROL IP Address Blacklist/Exempt List IPSec NAT Traversal Identify and Control Over 1400 Applications Automatic Real-Time Updates From FortiGuard Automatic IPSec Configuration Control Popular IM/P2P Apps Regardless of Port/ Network Dead Peer Detection Protocol: RSA SecurID Support AOL-IM Yahoo MSN ENDPOINT COMPLIANCE AND CONTROL SSL Single Sign-On Bookmarks ICQ MySpace Monitor & Control Hosts Running FortiClient Endpoint SSL Two-Factor Authentication Skype eDonkey Facebook Security LDAP Group Authentication (SSL) HIGH AVAILABILITY (HA) MANAGEMENT/ADMINISTRATION NETWORKING/ROUTING Active-Active, Active-Passive Console Interface (RS-232) Multiple WAN Link Support Stateful Failover (FW and VPN) WebUI (HTTP/HTTPS) DHCP Client/Server Device Failure Detection and Notification Telnet / Secure Command Shell (SSH) Policy-Based Routing Link Status Monitor Command Line Interface Dynamic Routing for IPv4 and IPv6 (RIP, OSPF, BGP, & Link failover Role-Based Administration Multicast for IPv4) Server Load Balancing Multi-language Support: English, Japanese, Korean, Multi-Zone Support Spanish, Chinese (Simplified & Traditional), French Route Between Zones WAN OPTIMIZATION Multiple Administrators and User Levels Route Between Virtual LANs (VDOMS) Bi-directional / Gateway to Client/Gateway Upgrades and Changes via TFTP and WebUI Multi-Link Aggregation (802.3ad) Integrated Caching and Protocol Optimization System Software Rollback IPv6 Support (Firewall, DNS, Transparent Mode, SIP, Accelerates CIFS/FTP/MAPI/HTTP/HTTPS/Generic TCP Configurable Password Policy Dynamic Routing, Admin Access, Management) Optional FortiManager Central Management VRRP and Link Failure Control VIRTUAL DOMAINS (VDOMs) sFlow Client Separate Firewall/Routing Domains LOGGING/MONITORING/VULNERABILITY Separate Administrative Domains Local Event Logging USER AUTHENTICATION OPTIONS Separate VLAN Interfaces Log to Remote Syslog/WELF Server Local Database 10 VDOM License Std. (more can be added) Graphical Real-Time and Historical Monitoring Windows Active Directory (AD) Integration SNMP Support External RADIUS/LDAP Integration WIRELESS CONTROLLER Email Notification of Viruses And Attacks Xauth over RADIUS for IPSEC VPN Unified WiFi and Access Point Management VPN Tunnel Monitor RSA SecurID Support Automatic Provisioning of APs Optional FortiAnalyzer Logging / Reporting LDAP Group Support On-wire Detection and Blocking of Rogue APs Optional FortiGuard Analysis and Management Virtual APs with Different SSIDs Service DATA CENTER OPTIMIZATION Multiple Authentication Methods Web Server Caching TCP Multiplexing TRAFFIC SHAPING HTTPS Offloading Policy-based Traffic Shaping WCCP Support Application-based and Per-IP Traffic Shaping Differentiated Services (DiffServ) Support Guarantee/Max/Priority Bandwidth Shaping via Accounting, Traffic Quotas

Note: This list is all-inclusive and may contain FortiOS features which are not available on all FortiGate/FortiWiFi appliances. Please consult FortiGate/FortiWiFi system documentation to determine feature availability for your appliance. Firewall Intrusion Prevention Fortinet firewall technology delivers complete content and network IPS technology protects against current and emerging network- protection by combining stateful inspection with a comprehensive level threats. In addition to signature-based threat detection, IPS suite of powerful security features. Application control, antivirus, performs anomaly-based detection which alerts users to any traffic IPS, Web filtering and VPN, along with advanced features such that matches attack behavior profiles. The Fortinet threat research as an extreme threat database, vulnerability management, flow- team analyzes suspicious behavior, identifies and classifies based inspection and active profiling work in concert to identify emerging threats, and generate new signatures to include with and mitigate the latest complex security threats. The security- FortiGuard Service updates. hardened FortiOS operating system works together with purpose- built FortiASIC processors to accelerate inspection throughput and identification of malware.

Features Features NAT, PAT and Transparent (Bridge) Automatic Database Updates Policy-Based NAT Protocol Anomaly Support SIP/H.323/SCCP NAT Traversal IPS and DoS Prevention Sensor VLAN Tagging (802.1Q) Custom Signature Support Vulnerability Management IPv6 Support IPv6 Support

Throughput FG-3040B FG-3140B Throughput FG-3040B FG-3140B 1518 Byte Packets 40 Gbps 58 Gbps IPS 6 Gbps 7 Gbps 512 Byte Packets 40 Gbps 55 Gbps 64 Byte Packets 40 Gbps 43 Gbps

Antivirus / Antispyware VPN Antivirus content inspection technology protects against viruses, Fortinet VPN technology provides secure communications between spyware, worms, and other forms of malware which can infect multiple networks and hosts, using SSL and IPsec VPN technologies. network infrastructure and endpoint devices. By intercepting Both services leverage our custom FortiASIC processors to provide and inspecting application-based traffic and content, antivirus acceleration in the encryption and decryption steps. The FortiGate protection ensures that malicious threats hidden within legitimate VPN service enforces complete content inspection and multi- application content are identified and removed from data streams threat protections including antivirus, intrusion prevention and before they can cause damage. FortiGuard subscription services Web filtering. Traffic optimization provides prioritization for critical ensure that FortiGate devices are updated with the latest malware communications traversing VPN tunnels. signatures for high levels of detection and mitigation.

Features Features Automatic Database Updates IPSec and SSL VPN Proxy-based Antivirus DES, 3DES, AES and SHA-1/MD5 Authentication Flow-based Antivirus PPTP, L2TP, VPN Client Pass Through File Quarantine SSL Single Sign-On Bookmarks IPv6 Support Two-Factor Authentication

Throughput FG-3040B FG-3140B Performance FG-3040B FG-3140B Antivirus (Proxy-based) 1.2 Gbps 1.2 Gbps IPSec VPN Throughput 17 Gbps 22 Gbps Antivirus (Flow-based) 2 Gbps 2 Gbps SSL VPN Throughput 500 Mbps 500 Mbps Maximum SSL VPN Users 22,000 22,000 Recommended WAN Optimization SSL-Encrypted Traffic Inspection Wide Area Network (WAN) optimization accelerates applications SSL-encrypted traffic inspection protects endpoint clients and over geographically dispersed networks, while ensuring multi- Web and application servers from hidden threats. SSL Inspection threat inspection of all network traffic. WAN optimization eliminates intercepts encrypted traffic and inspects it for threats prior to unnecessary and malicious traffic, optimizes legitimate traffic, and routing it to its final destination. It can be applied to client-oriented reduces the amount of bandwidth required to transmit data between SSL traffic, such as users connecting to cloud-based CRM site, applications and servers. Improved application performance and and to inbound Web and application server traffic. SSL inspection delivery of network services reduces bandwidth and infrastructure enables you to enforce appropriate use policies on encrypted Web requirements, along with associated expenditures. content and to protect servers from threats which may be hidden inside encrypted traffic flows.

Features Features Gateway-to-Gateway Optimization Protocol support: Bidirectional Gateway-to-client Optimization HTTPS, SMTPS, POP3S, IMAPS Web Caching Inspection support: Secure Tunnel Antivirus, Web Filtering, Antispam, Data Loss Prevention, SSL Offload Transparent Mode

Endpoint NAC Data Loss Prevention Endpoint NAC can enforce the use of FortiClient Endpoint Security DLP uses a sophisticated pattern-matching engine to identify and for users connecting to corporate networks. Endpoint NAC verifies prevent the transfer of sensitive information outside of your network FortiClient Endpoint Security installation, firewall operation and up- perimeter, even when applications encrypt their communications. to-date antivirus signatures before allowing network access. Non- In addition to protecting your organization’s critical data, Fortinet compliant endpoints, such as endpoints running applications that DLP provides audit trails to aid in policy compliance. You can select violate security policies can be quarantined or sent to remediation. from a wide range of configurable actions to log, block, and archive data, and quarantine or ban users.

Features Features Monitor & Control Hosts Running FortiClient Identification and Control Over Data in Motion Vulnerability Scanning of Network Nodes Built-in Pattern Database Quarantine Portal RegEx Based Matching Engine Application Detection and Control Common File Format Inspection Built-in Application Database International Character Sets Supported Flow-based DLP

Web Filtering Logging, Reporting & Monitoring Web filtering protects endpoints, networks and sensitive information FortiGate consolidated security appliances provide extensive against Web-based threats by preventing users from accessing logging capabilities for traffic, system, and network protection known phishing sites and sources of malware. In addition, functions. They also allow you to assemble drill-down and graphical administrators can enforce policies based on Website categories reports from detailed log information. Reports can provide historical to easily prevent users from accessing inappropriate content and and current analysis of network activity to aid with identification of clogging networks with unwanted traffic. security issues and to prevent network misuse and abuse.

Features Features HTTP/HTTPS Filtering Internal Log storage and Report Generation URL / Keyword / Phrase Block Graphical Real-Time and Historical Monitoring Blocks Java Applet, Cookies or Active X Graphical Report Scheduling Support MIME Content Header Filtering Graphical Drill-down Charts Flow-based Web Filtering Optional FortiAnalyzer Logging (including per VDOM) IPv6 Support Optional FortiGuard Analysis and Management Service High Availability Application Control High Availability (HA) configurations enhance reliability and increase Application control enables you to define and enforce policies for performance by clustering multiple FortiGate appliances into a thousands of applications running across networks regardless of single entity. FortiGate High Availability supports Active-Active and port or the protocol used for communication. The explosion of new Active-Passive options to provide maximum flexibility for utilizing Internet-based and Web 2.0 applications bombarding networks each member within the HA cluster. The HA feature is included today make application control essential, as most application as part of the FortiOS operation system and is available with most traffic looks like normal Web traffic to traditional firewalls. Fortinet FortiGate appliances. application control provides granular control of applications along with traffic shaping capabilities and flow-based inspection options.

Features Features Active-Active and Active-Passive Identify and Control Over 1,400 Applications Stateful Failover (FW and VPN) Traffic Shaping (Per Application) Link State Monitor and Failover Control Popular Apps Regardless of Port or Protocol Device Failure Detection and Notification Popular Applications include: Server Load Balancing AOL-IM Yahoo MSN KaZaa ICQ Gnutella BitTorrent MySpace WinNY Skype eDonkey Facebook and more

Virtual Domains Setup / Configuration Options Virtual Domains (VDOMs) enable a single FortiGate system to Fortinet provides administrators with a variety of methods and function as multiple independent virtual FortiGate systems. Each wizards for configuring FortiGate appliances during deployment. VDOM contains its own virtual interfaces, security profiles, routing From the easy-to-use Web-based interface to the advanced table, administration, and many other features. FortiGate VDOMs capabilities of the command-line interface, FortiGate systems offer reduce the complexity of securing disparate networks by virtualizing the flexibility and simplicity you need. security resources on the FortiGate platform, greatly reducing the power and footprint required as compared to multiple point products. Ideal for large enterprise and managed service providers.

Features Features Separate Firewall / Routing Domains Web-based User Interface Separate Administrative Domains Command Line Interface Over Serial Connection Separate VLAN Interfaces Pre-configured Settings from USB Drive Maximum VDOMs: 250 Default VDOMs: 10

Wireless Controller All FortiGate and FortiWiFi™ consolidated security platforms have an integrated wireless controller, enabling centralized management of FortiAP™ secure access points and wireless LANs. Unauthorized wireless traffic is blocked, while allowed traffic is subject to identity- aware firewall policies and multi-threat security inspection. From a single console you can control network access, update security policies, and enable automatic identification and suppression of rogue access points.

Features Unified WiFi and Access Point Management Automatic Provisioning of APs On-wire Detection and Blocking of Rogue APs Supports Virtual APs with Different SSIDs Supports Multiple Authentication Methods Technical Specifications FortiGate-3040B FortiGate-3140B Interfaces and Modules FortiGate-3040B/3140B consolidated Total Network Interfaces 20 22 security appliances also include: Hardware Accelerated 10-GbE SFP+ Interfaces 8 10 • Multiple deployment modes (Transparent/ Hardware Accelerated 1-GbE SFP Interfaces 10 Non-Accelerated 10/100/1000 Interfaces 2 Routing) for ease of installation Transceivers Included 2x SR SFP+ • Integrated Switch Fabric for very low latency Fortinet Storage Module (FSM) Expansion Slots (Total) 4 • Advanced Layer-2/3 routing for data center Local Solid State Disk Storage Included 64 GB SSD (1x FSM-064) USB Server 2 traffic optimization RJ45 Serial Console 1 • High Availability (Active/Active, Active/Passive, System Performance Clustering) for maximum uptime Firewall Throughput (1518 byte UDP packets) 40 Gbps 58 Gbps Firewall Throughput (512 byte UDP packets) 40 Gbps 55 Gbps • Virtual Domains (VDOMs) for multi-tenant Firewall Throughput (64 byte UDP packets) 40 Gbps 43 Gbps environments IPSec VPN Throughput (AES-256+SHA1) 17 Gbps 22 Gbps • Traffic Shaping and Prioritization ensure IPS Throughput 6 Gbps 7 Gbps performance of critical traffic Antivirus Throughput (Proxy-based) 1.2 Gbps Antivirus Throughput (Flow-based) 2 Gbps • WAN Optimization and Web Caching for Static IPSec VPN Tunnels (System / VDOM) 10,000 / 5,000 improved performance and lower costs Concurrent IPSec VPN Tunnels 64,000 • Local event logging and reporting for compliance Concurrent Sessions 4.0 Million and auditing New Sessions/Sec 100,000 Concurrent SSL-VPN Users (Recommended Max) 22,000 SSL VPN Throughput 500 Mbps MANAGEMENT OPTIONS Firewall Policies (VDOM/System) 50,000 / 100,000 Virtual Domains (Max / Default) 250 / 10 • Local Web-Based Management Interface Wireless Access Points Controlled 1,024 • Command Line Management Interface (CLI) Unlimited User Licenses Yes • Centralized management and analysis by Redundant Power Supplies (Hot Swappable) Yes Dimensions FortiManager and FortiAnalyzer Height 3.46 in (88 mm) Width 17.40 in (442 mm) Length 21.85 in (555 mm) Weight 35 lb (15.9 kg) 41 lb (18.6 kg) Rack Mountable Yes Environment Power Source 100 - 240 VAC, 50-60 Hz Current (Max) 3.50A /110V, 1.75A /220V 4.18A /110V, 2.09A /220V

Power Consumption (Avg) 315 W 383 W Actual performance values may vary depending on the network traffic and system Power Consumption (Max) 378 W 460 W configuration. Firewall performance is based on 64, 512 and 1518 Byte UDP packets processed with the FortiGate-3040B/3140B appliance operating in NAT mode. VPN Heat Dissipation 1290 BTU/h 1570 BTU/h performance is based on 512 Byte UDP packets processed with the FortiGate-3040B/3140B Operating Temperature 32 – 104 deg F (0 – 40 deg C) appliance using AES-256+SHA1 encryption algorithms. Antivirus performance is measured using HTTP traffic with 32 KB file attachments and the FortiGate-3040B/3140B configured Storage Temperature -31 – 158 deg F (-35 – 70 deg C) to use the regular antivirus database. IPS performance is measured base on NSS like test Humidity 20 to 90% non-condensing methodology with 44K HTTP files. Compliance Regulatory Compliance FCC Class A Part 15, UL/CUL, C Tick, VCCI

Ordering Info Product Description SKU FortiGate-3040B, 8 SFP+ 10-Gig ports (2 SFR+ SR-type transceivers included), 10 SFP 10/100/1000 FortiASIC accelerated ports, 2 SFP 10/100/1000 ports, 4 FSM FG-3040B Slots, 1 FSM-064 with 64 GB SSD storage, and dual AC power supplies FortiGate-3140B, 10 SFP+ 10-Gig ports (2 SFR+ SR-type transceivers included), 10 SFP 10/100/1000 FortiASIC accelerated ports, 2 SFP 10/100/1000 ports, 4 FSM FG-3140B Slots, 1 FSM-064 with 64 GB SSD storage, and dual AC power supplies Optional Accessories SKU Fortinet Storage Module (FSM), 64 GB Solid State Drive for FortiGate with FSM slot FSM-064 10-Gig transceiver, Short Range SFP+ module for all FortiGate models with SFP+ interfaces FG-TRAN-SFP+SR 10-Gig transceiver, Long Range SFP+ module for all FortiGate models with SFP+ interfaces FG-TRAN-SFP+LR

GLOBAL HEADQUARTERS EMEA SALES OFFICE – FRANCE APAC SALES OFFICE – SINGAPORE Fortinet Incorporated Fortinet Incorporated Fortinet Incorporated 1090 Kifer Road, Sunnyvale, CA 94086 USA 120 rue Albert Caquot 300 Beach Road #20-01 The Concourse, Tel +1.408.235.7700 06560, Sophia Antipolis, France Singapore 199555 Fax +1.408.235.7737 Tel +33.4.8987.0510 Tel +65-6513-3734 www.fortinet.com/sales Fax +33.4.8987.0501 Fax +65-6295-0015

Copyright© 2011 Fortinet, Inc. All rights reserved. Fortinet®, FortiGate®, and FortiGuard®, are registered trademarks of Fortinet, Inc., and other Fortinet names herein may also be trademarks of Fortinet. All other product or company names may be trademarks of their respective owners. Performance metrics contained herein were attained in internal lab tests under ideal conditions, and performance may vary. Network variables, different network environments and other conditions may affect performance results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract, signed by Fortinet’s General Counsel, with a purchaser that expressly warrants that the identified product will perform according to the performance metrics herein. For absolute clarity, any such warranty will be limited to performance in the same ideal conditions as in Fortinet’s internal lab tests. Fortinet disclaims in full any guarantees. Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without notice, and the most current version of the publication shall be applicable. Certain Fortinet products are licensed under U.S. Patent No. 5,623,600.

FST-PROD-DS-GT3K2 FG-3040B-3140B--R5.1-201110